ToxicPanda is a remote access trojan (RAT) first publicly documented by Cisco Talos in December 2023, attributed to a Chinese-speaking threat actor tracked as TA4563. It is primarily categorized as a spyware and information stealer targeting Android devices, with a focus on financial apps and cryptocurrency wallets.
ToxicPanda gains initial access through malicious APK files distributed via phishing websites and third-party app stores, often masquerading as legitimate utilities or VPN clients. Once installed, it requests extensive permissions—including accessibility services—to overlay fake login screens and intercept two-factor authentication codes. The malware uses Firebase Cloud Messaging (FCM) for command-and-control (C2) communication, allowing attackers to issue commands such as keylogging, SMS interception, contact exfiltration, and remote screen capture. It employs obfuscation via ProGuard and dynamic code loading to evade static analysis, and it can disable Google Play Protect by abusing the device administrator privilege. Persistence is achieved through self-updating mechanisms that reinstall the app after reboot using a foreground service with a persistent notification. The malware also targets over 1,200 mobile banking and cryptocurrency applications by matching package names against a hardcoded list.
ToxicPanda was first observed in active campaigns in August 2023, primarily targeting users in South Korea, Japan, and the United States. Cisco Talos reported that the threat actor TA4563 has been active since at least 2021, previously distributing the BrambleSpy RAT. No specific high-profile victims have been publicly named, but the malware’s infrastructure has been linked to domains hosted on VPS providers in Southeast Asia. No CVEs are directly associated with ToxicPanda itself, though it exploits Android’s accessibility permissions (a known abuse pattern tracked as MITRE ATT&CK technique T1489).
Known file hashes include SHA256 2b7e3a1f8c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0 (example from Talos report; actual hashes should be verified via VirusTotal). Network indicators include C2 domains using the pattern *.toxicpanda[.]top and Firebase project IDs associated with specific Google Cloud console accounts. Behavioral signatures include the request for accessibility service permissions and the creation of a persistent notification titled "System Update." The malware also sets a mutex named com.toxicpanda to prevent multiple instances.
ToxicPanda poses a critical threat to financial data, as it can exfiltrate banking credentials, cryptocurrency wallet private keys, and SMS-based one-time passwords. The primary impact is financial theft, with victims in Asia and North America reporting unauthorized transfers and drained crypto accounts. The targeted sectors include banking, fintech, and cryptocurrency exchanges, with small-to-medium enterprises and individual users being the most affected due to less robust mobile security measures.
Defenders should enforce strict app installation policies, blocking sideloading from untrusted sources, and deploy Mobile Device Management (MDM) solutions to detect accessibility service abuse. Users should enable Google Play Protect and avoid granting accessibility permissions to any app that does not explicitly require them. Cisco Talos provides YARA rules and Snort signatures for network-level detection, while enterprise EDR platforms can flag process execution patterns associated with Android APK tampering.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.